Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityHard
A software development team is adopting a serverless architecture for a new application. They are concerned about the security implications of third-party libraries and dependencies used in their Lambda functions. To mitigate supply chain risks, they want to ensure that only approved and scanned code is deployed to production, and that functions are regularly checked for known vulnerabilities. Which security best practice is most relevant for addressing these concerns in a serverless environment?
- AEnforcing code signing and integrity checks for deployed functions
- BConfiguring DDoS protection for the serverless application
- CUtilizing Security Groups for network isolation of Lambda functions
- DImplementing a robust WAF in front of the API Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. Enforcing code signing and integrity checks for deployed functions
Enforcing code signing and integrity checks ensures that only trusted, untampered code is deployed. Coupled with scanning for vulnerabilities in dependencies, this directly mitigates supply chain risks by verifying the authenticity and security of the code before and during deployment.
Why the other options are wrong
- B. DDoS protection mitigates denial-of-service attacks, which is important but does not address supply chain vulnerabilities in the function's code.
- C. Security Groups provide network isolation, but Lambda functions typically run in a managed VPC and their core security concern is the code itself, not network ingress/egress from the function runtime.
- D. WAFs protect against web attacks at the edge, but do not address vulnerabilities within the Lambda function's code or dependencies.
Serverless Supply Chain Security
Security practices focused on protecting serverless applications from vulnerabilities introduced through third-party libraries, open-source components, and the development pipeline.
- Includes dependency scanning for known vulnerabilities (SCA).
- Emphasizes code signing and integrity verification.
- Integrates security checks throughout the CI/CD pipeline for functions.
Memory trick: For serverless, 'Code Signing' is like putting a tamper-proof seal on your function.